目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2022-46604 PoC — Tecrail Responsive FileManager 代码问题漏洞

来源
关联漏洞
标题: Tecrail Responsive FileManager 代码问题漏洞 (CVE-2022-46604)
Description:Tecrail Responsive FileManager是意大利Tecrail公司的一款使用PHP语言编写的开源文件管理器。该产品支持视频、图像或其他文件的上传和管理。 Tecrail Responsive FileManager v9.9.5及之前版本存在安全漏洞,该漏洞源于允许攻击者绕过文件扩展名检查机制并上传精心制作的PHP文件,从而导致任意代码执行。
Description
Responsive FileManager v.9.9.5 vulnerable to CVE-2022-46604.
介绍
# ResponsiveFileManager-CVE-2022-46604
Responsive FileManager v.9.9.5 vulnerable to CVE-2022-46604 (File Creation Extension Bypass which leads to RCE).

The current exploit is made in Python 3 and exploits the vulnerability to upload a webshell which allows the remote execution of commands in the vulnerable host.

## References
- Exploit Database (Exploit-DB): https://www.exploit-db.com/exploits/51251
- Packet Storm Security: https://packetstormsecurity.com/files/171720/Responsive-FileManager-9.9.5-Remote-Shell-Upload.html

### Demo

![CVE-2022-46604 exploit PoC](CVE-2022-46604-exploit-PoC.png "CVE-2022-46604 exploit PoC")
文件快照

登录后查看神龙缓存的 POC 文件快照

登录查看
备注
    1. 建议优先通过来源进行访问。
    2. 本地 POC 快照面向订阅用户开放;当原始来源失效或无法访问时,本地镜像作为订阅权益的一部分提供。
    3. 持续抓取、验证、维护这份 POC 档案需要不少投入,因此本地快照已纳入付费订阅。您的订阅是让这份资料能继续走下去的关键,由衷感谢。 查看订阅方案 →